Tres nuevos avisos de seguridad
Cybersecurity Classified by Officially
INCIBE ha coordinado la publicación de 4 vulnerabilidades de severidad media que afectan a Entradium de Crocantickets, software para la creación de eventos. Las vulnerabilidades han sido descubiertas por Cosme Vázquez Tomé.
A estas vulnerabilidades se les han asignado los siguientes códigos, puntuación base CVSS v4.0, vector del CVSS y el tipo de vulnerabilidad CWE de cada vulnerabilidad:
Las vulnerabilidades han sido solucionadas por el equipo de Crocantickets en las versiones 20260409151659 y 20260409153543.
CVE-2026-7173: vulnerabilidad de tipo Cross-Site Scripting en Entradium, de Crocantickets. La explotación de esta vulnerabilidad podría permitir a un atacante remoto enviar una URL especialmente diseñada a la víctima y robar sus datos de sesión.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.incibe.es/node/669523
Officially imported this from INCIBE’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- INCIBE — imported from official source
- Official source
- https://www.incibe.es/rss.xml RSS
- Imported
- October 01, 2026 09:30
- Versions
- 1 recorded
- Identity
669523 at https://www.incibe.es